Critical Thinking - Bug Bounty Podcast · Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)

Episode 152: GeminiJack and Agentic Security with Sasi Levi

December 11, 2025·1 hr 22 min·5 clips
The payload turned Gemini's own HTTP request into a carrier for internal data from Gmail, Calendar, and Google Docs.
1. Critical Thinking - Bug Bounty Podcast focuses on Sasi Levi's Vertex AI and Gemini Enterprise prompt-injection research. 2. Sasi Levi is the guest, and the hosts frame him as a long-time Google bug bounty hunter and Noma Security researcher. 3. The episode asks how Gemini-style agents can be pushed to expose workspace data through indirect prompt injection and RAG. 4. Levi says Google first had a combined Vertex AI and Gemini Enterprise test setup, then split the products after his report. 5. He describes starting with Google Docs, writing simple prompts like mixing red and yellow, and watching Gemini summarize the page. 6. Levi then moved to Vertex AI, AI applications, and agent space because he wanted a Gemini with more tools and more power. 7. He says the RAG sources included Gmail, Calendar, and Google Docs, and a question about sales could fan out across all of them. 8. The guest explains that the client interface showed what Gemini was searching, which helped him infer how the system assembled context. 9. He describes using benign questions first, then adding malicious content after the model appeared to trust the conversation. 10. He says the eventual payload used HTML injection and an image request to carry internal data out in an HTTP request. 11. Levi reports that Gmail exposed only email subjects, Google Docs exposed only titles, and Calendar exposed more fields such as descriptions and files. 12. He says the Calendar path was the most powerful because it included location, description, and file data in one flow. 13. The hosts compare the bug to classic injection problems like SQL injection and XSS because user input was treated as prompt context. 14. Levi says he created a term called "context" for the way models blend system instructions with user input. 15. He also describes a trust-negotiation tactic where simple questions like colors can lower guardrails before asking for secrets. 16. The guest says he sometimes uses emotional social-engineering prompts, including asking for help because his son is in the car. 17. The interview style is technical and conversational, with the hosts stopping Levi to clarify Vertex AI, Gemini, and RAG behavior. 18. The energy is practical and exploratory, with frequent back-and-forth on payload shape, product boundaries, and reporting impact. 19. Listeners who follow Google Cloud, prompt injection, and AI bug bounty work will get the most from this episode. 20. Listeners wanting abstract AI theory without exploit details may skip it.

As heard by us

A practical bug bounty conversation with clear process detail and a career story rooted in security work.

A practical episode that starts with ThreatLocker elevation control and then moves into Sasi Levi's path through software engineering, R and D, and late-night bug bounty work.

Read the full review in PlayNext →

Why you'd press play

You want a bug bounty episode centered on ThreatLocker elevation control, plus a first-hand career origin story and a news-heavy bug bounty segment.

Read the full recommendation in PlayNext →
Listen to the show on